lov-feedback-loop

Fail

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: HIGHOBFUSCATIONREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [OBFUSCATION]: The skill's primary instructions (SKILL.md.enc), manifest, and all functional scripts are encrypted using AES-256-GCM. This technique hides the skill's true intent and behavior from both users and automated security analysis tools.
  • [REMOTE_CODE_EXECUTION]: The instructions in SKILL.md direct the agent to download and execute an external tool, lovstudio-skill-helper, via the uvx package runner. This tool is tasked with decrypting and running the skill's hidden logic, creating an unverified remote code execution path.
  • [DYNAMIC_EXECUTION]: The skill employs a runtime execution model where it decrypts Python scripts (such as scripts/feedback_store.py) and immediately executes them using the helper tool (e.g., uvx lovstudio-skill-helper exec feedback-loop ...). This dynamic execution of opaque code bypasses standard safety auditing procedures.
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform multiple shell operations, including license activation via npx lovstudio license and skill installation via npx lovstudio skills add, which involve executing commands from the lovstudio vendor ecosystem.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 11, 2026, 02:48 AM
Security Audit — agent-trust-hub — lov-feedback-loop